Vulnerabilities > Atlassian > Confluence Server > 6.14.1

DATE CVE VULNERABILITY TITLE RISK
2021-05-07 CVE-2020-29445 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Confluence Server
Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
network
low complexity
atlassian CWE-918
4.0
2021-01-19 CVE-2020-29450 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature.
network
low complexity
atlassian CWE-434
4.0
2020-04-22 CVE-2019-20102 Cross-site Scripting vulnerability in Atlassian Confluence Server
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
network
atlassian CWE-79
4.3
2019-12-19 CVE-2019-15006 Improper Control of Dynamically-Managed Code Resources vulnerability in Atlassian Confluence and Confluence Server
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center.
network
atlassian CWE-913
5.8
2019-08-29 CVE-2019-3394 Path Traversal vulnerability in Atlassian Confluence and Confluence Server
There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting.
network
low complexity
atlassian CWE-22
4.0
2019-04-30 CVE-2018-20239 Cross-site Scripting vulnerability in Atlassian products
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter.
network
atlassian CWE-79
3.5
2019-04-18 CVE-2019-3398 Path Traversal vulnerability in Atlassian Confluence
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
network
low complexity
atlassian CWE-22
critical
9.0
2019-03-25 CVE-2019-3396 Path Traversal vulnerability in Atlassian Confluence
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
network
low complexity
atlassian CWE-22
critical
10.0
2019-03-25 CVE-2019-3395 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Confluence and Confluence Server
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
network
low complexity
atlassian CWE-918
7.5